CVE-2025-1010

Publication date

2025-02-04 13:58:52

Family

mozilla

State

PUBLISHED

Description

An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.